Privacy Policy

Last updated: 2026-05-13

Sentrovia ("we", "us", "our") is a corporate PM training platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the choices you have. It applies to all visitors and users of Sentrovia.

1. Data we collect

  • Account data: name, email address, password hash, organization, role assignments, and credentials (PMP candidate status).
  • Usage data: exam attempts, scores, flashcard reviews, tutorial progress, AI assistant conversations, project records you create.
  • Technical data: IP address, browser user-agent, device type, last-login timestamps, and session cookies.
  • Org data: for enterprise customers, membership records, competency aggregates, and audit-log entries tied to your account.
  • Payment data: billing email, plan tier, subscription state. Card details are stored by our payment processor (Stripe), not by us.

2. Lawful basis (GDPR Art. 6)

We process personal data under one of these lawful bases:

  • Contract: to deliver the service you signed up for.
  • Legitimate interests: to operate, secure, and improve the platform.
  • Consent: for non-essential cookies and marketing communications.
  • Legal obligation: tax records, audit logs, fraud prevention.

3. How we use your data

  • Deliver the learning experience: exams, flashcards, AI coach, project tooling.
  • Provide team-level competency reporting to your organization's admin (no individual question-level details are surfaced to organizational admins).
  • Send transactional emails: verification, password reset, billing.
  • Detect abuse and enforce rate limits.

4. Data retention

  • Account data: retained while your account is active. Deleted within 30 days of account closure unless legally required to retain longer.
  • Exam attempts and flashcard reviews: retained for 24 months after your last activity to support competency trending.
  • Audit logs: retained 7 years for compliance.
  • Backups: full backups retained 35 days on rolling basis.

5. Who we share data with

We do not sell personal data. We share it with:

  • Sub-processors: our hosting provider (Vercel), database provider (Neon / Postgres), email delivery (Resend), payment processing (Stripe), AI model providers (Anthropic), and error monitoring (Sentry).
  • Your organization: if you signed up through an org, your org admin sees your aggregate progress and membership status.
  • Legal compulsion: if required by law or to protect rights.

6. Data residency & cross-border transfers

Primary data is stored in the United States. Our hosting infrastructure operates globally via Vercel edge regions. EU customers may request EU-region hosting under a Data Processing Agreement; contact our DPO at the address below.

Where personal data is transferred outside the EEA, UK, KSA, or UAE to our sub-processors (e.g. hosting in the United States), we rely on one or more of the following safeguards as appropriate to the recipient and jurisdiction:

  • The EU-US Data Privacy Framework adequacy decision for DPF-certified recipients;
  • Standard Contractual Clauses (SCCs) — Module 1 (controller-to-controller) or Module 2 (controller-to-processor), as applicable — for transfers to recipients not covered by an adequacy decision;
  • UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs for transfers originating in the UK;
  • Equivalent local mechanisms under KSA PDPL and UAE PDPL where these apply.

A current list of sub-processors and the transfer mechanism in use for each is available on request from the DPO contact below.

7. Your rights

  • Access (GDPR Art. 15): request a copy of all data we hold on you.
  • Rectification (Art. 16): correct inaccurate data.
  • Erasure (Art. 17): request deletion of your account and data.
  • Portability (Art. 20): export your data in machine-readable JSON.
  • Restriction (Art. 18): ask us to stop processing certain data.
  • Objection (Art. 21): object to processing based on legitimate interests.
  • CCPA / CPRA: California residents have analogous rights including the right to know and the right to delete.

To exercise any of these rights, email privacy@coropmp.com. We respond within 30 days.

8. Cookies

See our Cookie Policy for details on the cookies we use and how to control them. We do not set non-essential cookies without your consent.

9. Security

Passwords are hashed with bcrypt. Session tokens are httpOnly + SameSite=Lax + Secure-in-production. TOTP-based 2FA is available on every account. We maintain an audit log of privileged actions. Our security incident response process targets notification within 72 hours of a confirmed breach.

10. Children

Sentrovia is intended for adult learners (16+). We do not knowingly collect data from children under 16. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes will be announced via email and in-app banner at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

Data controller: Sentrovia, Inc.
Email: privacy@coropmp.com
Data Protection Officer: dpo@coropmp.com
EU representative: contact us at the email above to be routed to our EU rep.